Skip to main content

Positive Technologies (dbugs)

ProductPositive Technologies vulnerability database (dbugs)
Records still shown as active1
First contacted2026-08-08
Channels trieddbugs@
StatusAwaiting response

Records

CVE-2025-15603

Authoritative stateREJECTED at cve.org and NVD since 2026-06-18
Withdrawn byVulDB, the issuing CNA, as a false positive
Their entryPT-2026-24109, published and last updated 2026-03-09
What it displaysAn active vulnerability in open-webui, weak WEBUI_SECRET_KEY randomness, CVSS 3.7 Low, annotated "The exploit has been publicly disclosed", with the recommendation to "update to a version of open-webui greater than 0.6.16"
Our assessmentCVE-2025-15603

The score matches the CNA, so this is a status problem rather than a scoring one: the entry was last updated more than three months before the withdrawal and has not re-synced.

What makes it worse than a stale row is the recommendation. The entry instructs the reader to upgrade in order to remediate an identifier that no longer exists, which turns a data-freshness defect into a maintenance action taken on false grounds.


Contact log

DateChannelOutcome
2026-08-08dbugs@Awaiting response

See also

This content is for informational purposes only and does not constitute a warranty, guarantee, or contractual commitment. Open WebUI is provided "as is." See your license for applicable terms.